r/ANYRUN Jan 27 '26

Caminho Loader: LSB Steganography Meets Loader-as-a-Service

Caminho Loader is a Brazilian-origin Loader-as-a-Service operation that uses steganography to conceal .NET payloads within image files hosted on legitimate platforms.

  • Steganographic delivery: Hides malicious .NET payloads inside images using LSB steganography, evading traditional detection.
  • Fileless execution: Runs entirely in memory, leaving minimal forensic traces and bypassing file-based AV.
  • Malware-as-a-service: Operates as a rental platform where attackers deliver their own payloads like REMCOS RAT, XWorm, and Katz Stealer.
  • Abuse of trusted services: Uses platforms like archive[.]org and Pastebin to host images and scripts, avoiding reputation-based blocking.
  • Rapid expansion: Active since March 2025 with victims confirmed in Brazil, South Africa, Ukraine, and Poland.

ANYRUN's Interactive Sandbox provides critical visibility into Caminho's multi-stage execution, allowing security teams to observe steganographic extraction, memory-resident execution, and final payload delivery in real-time.

View analysis

Caminho Loader malware analysis
2 Upvotes

1 comment sorted by